51
© 2017 Denim Group All Rights Reserved Building a world where technology is trusted. ThreadFix 2.5 Application Security at DevOps Speed April 18th, 2017 Dan Cornell, CTO Kyle Pippin, Product Manager

ThreadFix 2.5 Webinar

Embed Size (px)

Citation preview

Page 1: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Building  a  world  where  technology  is trusted. ThreadFix 2.5Application  Security  at  DevOps  SpeedApril  18th,  2017

Dan  Cornell,  CTOKyle  Pippin,  Product  Manager

Page 2: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Agenda

Page 3: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Agenda• Application  Security  and  DevOps• ThreadFix Background• ThreadFix 2.5  Release• Coming  Up  in  the  2.5  Series

2

Page 4: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Application  Security  and  DevOps

Page 5: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

DevOps  Is  Coming

Page 6: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Some  Security  Teams  Will  Adapt

(Others  Will  Not)

5

Page 7: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Use  This  Transition  to  Your  Advantage

6

Page 8: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Move  Security  to  the  Left  and  Get  Buy-­In

7

Page 9: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Better  Security  Insight,  More  Often

8

Page 10: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

What  Does  Application  Security  Want

• Reduce  Risk  Exposure

• Introduce  Fewer  Vulnerabilities

• Find  Vulnerabilities  Early

• Fix  Vulnerabilities  Quickly

9

Page 11: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

What  Do  DevOps  Teams  Want?

10

Page 12: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

How  Do  We  Make  This  a  Reality?

11

Page 13: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Application  Security  Testing  in  CI/CD  Pipelines

12

Page 14: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

AppSec Testing  Policies  for  DevOps

13

Page 15: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  Tradeoffs

14

Page 16: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Decision-­Making  Factors

15

Page 17: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Reporting  Recommendations

(Hint:  Not  With  These)

16

Page 18: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

ThreadFix Background

Page 19: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

ThreadFix Overview• Create  a  consolidated  view  of  your  applications  and  vulnerabilities

• Prioritize  application  risk  decisions  based  on  data

• Translate  vulnerabilities  to  developers  in  the  tools  they  are  already  using

18

Page 20: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

ThreadFix Overview

19

Page 21: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Create  a  consolidated  view  of  your  

applications  and  vulnerabilities

20

Page 22: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Application  Portfolio  Tracking

21

Page 23: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Vulnerability  Consolidation

22

Page 24: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Prioritize  application  risk  decisions  based  on  

data

23

Page 25: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Vulnerability  Prioritization

24

Page 26: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Prioritization  with  Hotspot

Page 27: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Reporting  and  Metrics

26

Page 28: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Translate  vulnerabilities  to  developers  in  the  tools  they  are  already  

using

27

Page 29: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Defect  Tracker  Integration

28

Page 30: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

ThreadFix 2.5  Release

Page 31: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Secure  DevOps with  ThreadFix

• What  does  your  pipeline  look  like?

http://www.slideshare.net/mtesauro/mtesauro-­keynote-­appseceu http://www.slideshare.net/denimgroup/rsa2015-­blending-­theautomatedandthemanualmakingapplicationvulnerabilitymanagementyourally

https://blog.samsungsami.io/development/security/2015/06/16/getting-­security-­up-­to-­speed.html

Page 32: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

AppSec Testing  for  DevOps

• Configuring  Testing  Policies

• AppSec Testing  for  DevOps  in  Action

Page 33: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Policy  Configuration• Testing• Synchronous• Asynchronous

• Decision• Reporting

32

Blog  Post:  Effective  Application  Security  Testing  in  DevOps  Pipelineshttp://www.denimgroup.com/blog/2016/12/effective-­application-­security-­testing-­in-­devops-­pipelines/

https://www.denimgroup.com/resources/effective-­application-­security-­for-­devops/

Page 34: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  Configuration

33

Page 35: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  Configuration

34

Page 36: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Decision  Configuration

35

Page 37: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Decision  Configuration

36

Page 38: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Reporting  Configuration

37

Page 39: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Reporting  Configuration

38

Page 40: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Reporting  Configuration

39

Page 41: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Reporting  Configuration

40

Page 42: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

41

Page 43: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

42

Page 44: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

43

Page 45: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

44

Page 46: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

45

Page 47: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

46

Page 48: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Testing  in  Action

47

Page 49: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Coming  Up  in  the  2.5  Series

Page 50: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Coming  Soon• Support  for  more  SAST  and  DAST  tools

• “Easy  Mode”  for  CI/CD  plugins

Page 51: ThreadFix 2.5 Webinar

©  2017  Denim  Group  – All  Rights  Reserved

Building  a  world  where  technology  is trusted.

@denimgroupwww.denimgroup.com

50

www.threadfix.it